Digital Trust Dimensions and Protection Motivation as Drivers of Behavioural Biometrics Acceptance in Malaysian E-Wallets
This study utilizes an extended Protection Motivation Theory model to demonstrate that among Malaysian e-wallet users, Benevolence Trust is the strongest predictor of behavioural biometric acceptance, surpassing other trust dimensions and security appraisals, thereby offering critical insights for enhancing digital trust and guiding regulatory implementation.
Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
In the bustling digital marketplaces of today, a quiet revolution is taking place in how we prove who we are. For decades, security relied on things we could hold or remember: a password, a fingerprint, or a code sent to a phone. But as financial fraud has grown more sophisticated, these static defenses have begun to show cracks. In their place, a new approach has emerged that does not ask for a password at all. Instead, it watches how we move. This is behavioural biometrics, a technology that learns the unique rhythm of a person's life on their device. It notices the specific pressure of a thumb on a screen, the speed of a swipe, and the way a phone is held while walking. It works in the background, invisible to the user, creating a continuous stream of proof that the person holding the device is the rightful owner.
Yet, for this technology to work, people must be willing to let it watch them. This creates a delicate tension between safety and privacy. If a system is too intrusive, people will reject it; if it is not trusted, they will not use it. Researchers have long known that trust is the key to unlocking new technologies, but they have often treated trust as a single, blurry feeling. A new study from Malaysia seeks to untangle this feeling, asking whether people trust a company because they believe it is skilled, because they believe it is honest, or because they believe it genuinely cares about them. By testing these distinct ideas against the backdrop of a rapidly growing digital economy, the researcher found that the answer lies not in technical prowess, but in a sense of genuine care.
Malaysia has become a fascinating laboratory for this question. The country's digital payment sector has exploded in recent years, with billions of transactions flowing through e-wallets every year. This convenience, however, has attracted a wave of online scams, costing users hundreds of millions of dollars in losses. In response, financial institutions are turning to behavioural biometrics as a shield. Unlike a fingerprint scanner that only checks a user once at the start of a transaction, this technology monitors the user constantly. It can detect if a fraudster has taken over an account by noticing that the way they type or hold the phone is different from the real owner's usual patterns. The technology is effective, but it requires a leap of faith from the user. They must agree to share intimate details of their daily interactions with a company, trusting that this data will be used only to protect them.
To understand what drives this leap of faith, a researcher at the University of Technology Malaysia surveyed over two hundred active e-wallet users. They wanted to see if the standard theories of security behavior could explain why someone would accept this invisible guardian. They focused on two main ideas. First, they looked at how people assess danger: do they feel vulnerable to fraud, and do they believe the new technology can actually stop it? Second, and more importantly, they broke down the concept of trust into three separate pillars. The first pillar is competence: the belief that the company has the technical skill to do the job right. The second is integrity: the belief that the company follows the rules and keeps its promises. The third is benevolence: the belief that the company truly has the user's best interests at heart and will not exploit their data for profit.
The researcher asked participants to rate their feelings on these various points and then measured their willingness to use the new authentication system. The results were clear and pointed in a specific direction. While the fear of fraud and the belief that the technology works were important, they were not the strongest drivers. The most powerful force shaping a user's decision was benevolence trust. In other words, people were far more likely to accept this continuous monitoring if they believed the company genuinely cared about their well-being. This finding held true even when the researcher accounted for the company's technical skill and its adherence to regulations.
This discovery challenges a common assumption in the tech world. Many companies operate under the belief that if they build a system that is technically perfect and strictly follows the law, users will automatically trust them. The study suggests this is not enough. In a context where data collection is invisible and continuous, users cannot see the code or the security protocols. They cannot verify the company's competence directly. Instead, they rely on a gut feeling about the company's intentions. The research indicates that when users feel a company is benevolent—when they believe the company is on their side and will not misuse their data—that feeling outweighs the belief that the company is merely competent or rule-abiding.
The study also revealed a subtle shift in how regulations are perceived. Malaysia recently updated its data protection laws to classify behavioural data as sensitive, a move that was expected to make "integrity" the most critical factor. Surprisingly, while integrity remained important, it did not surpass benevolence. This suggests that for the average user, the emotional connection of being cared for is more persuasive than the legal assurance of being protected. The researcher found that users who felt a company was benevolent were the ones most ready to adopt the technology, regardless of how much they knew about the specific laws governing it.
The implications of these findings are significant for the future of digital security. The study suggests that for behavioural biometrics to become a standard part of daily life, companies must change how they talk to their customers. Simply listing technical specifications or citing compliance with new laws may not be enough to win over the public. Instead, providers need to communicate a clear, verifiable commitment to the user's welfare. They must show, through their actions and policies, that they are collecting data solely to protect the user and not to sell it or use it for other commercial gains. If a company can establish this sense of genuine care, the study indicates that users will be far more willing to let the invisible guardian watch over their digital lives.
Ultimately, this research highlights a fundamental truth about the digital age: technology is not just about what works, but about who is holding the reins. As Malaysia and the rest of the world move toward a future where our devices know us better than we know ourselves, the success of these systems will depend less on the complexity of the algorithms and more on the simplicity of trust. The study confirms that in the end, people do not just want a system that is smart; they want a partner that is kind.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.